Data Privacy & Security

Document version 2.0 — Last updated September 21, 2026

1. Overview

Smart Assistant is a Zoho CRM sidebar extension that provides unified visibility across a contact’s CRM profile, Zoho Books financial records, Zoho Desk support tickets, and an optional AI-generated strategic summary. It runs entirely inside Zoho CRM, either as a Related List widget on the contact page or as a view-page button that opens in an in-CRM popup.

This document describes how data is handled throughout the extension’s operation, including the limited cases in which data leaves your Zoho organization.

2. Authorization & Access

Smart Assistant does not ask users for Zoho credentials and does not run its own login, password, or token-collection flow. Access is granted through a Zoho CRM Connection that your organization’s administrator creates and authorizes inside Zoho CRM (Setup → Developer Hub → Connections).

2.1 How It Works

  1. Your Zoho administrator installs Smart Assistant and creates the Connection in your CRM organization.
  2. The administrator is shown Zoho’s official consent screen and approves the read-only scopes listed below.
  3. Zoho stores and manages the resulting authorization within Zoho. Smart Assistant never receives the tokens.
  4. When a user opens a contact, the widget calls Zoho through that Connection and renders whatever data the user is already permitted to see in Zoho.

Because authorization lives inside Zoho, it is admin-controlled: administrators can review, re-scope, or revoke it at any time from the Connections screen, and access follows each user’s existing Zoho permissions.

2.2 Scope of Access

ScopePurpose
ZohoCRM.modules.READRead contact and account data from the CRM
ZohoBooks.contacts.READRead customer/contact records in Zoho Books
ZohoBooks.invoices.READRead invoices (overdue status and balances) from Zoho Books
ZohoBooks.payments.READRead payment records from Zoho Books
ZohoBooks.settings.READRead organization details to resolve the Zoho Books organization
Desk.tickets.READRead support ticket history from Zoho Desk
Desk.contacts.READRead contact data embedded in Desk tickets

All requested scopes are read-only. Smart Assistant never creates, updates, or deletes CRM, Books, or Desk records.

3. Data Flow Architecture

Business data lives in Zoho and is read from Zoho. The only data that reaches Smart Assistant’s infrastructure is the context needed to produce an optional AI summary.

┌────────────────────────── Zoho CRM (in-CRM widget) ──────────────────────────┐
│                                                                             │
│   Smart Assistant widget / button ── Zoho Connection (read-only) ──► Zoho    │
│   (Related List + view-page popup)                                   APIs    │
│                    │                                          (CRM/Books/   │
│                    │ HTTPS                                     Desk)         │
└────────────────────┼────────────────────────────────────────────────────────┘
                     │
                     │  viewing context only (for the AI summary)
                     ▼
          ┌────────────────────────┐   HTTPS   ┌────────────────────────┐
          │  Smart Assistant       │──────────►│  AI model provider     │
          │  backend (AI summary)  │           │  (Gemini by default)   │
          └────────────────────────┘           └────────────────────────┘

3.1 Step-by-Step Data Flow

  1. User opens a contact in Zoho CRM → the Smart Assistant widget or button loads in the CRM UI.
  2. The widget reads data through the Connection — CRM contact and account details, Books invoices/payments, and Desk tickets — directly via Zoho’s APIs.
  3. Data is rendered in the browser inside Zoho. Smart Assistant’s servers are not involved in reading this data.
  4. Optional AI summary: to generate the strategic summary, the widget sends the contact context it is currently displaying to our backend, which forwards it to the configured AI provider and returns the summary text.
  5. Nothing is persisted beyond a short-lived in-memory cache (see §5).

3.2 What Is NOT Stored

4. Data Sent to Our Backend

Our backend serves the extension’s pages and provides one functional endpoint: the AI summary.

4.1 AI Summary Endpoint

AspectDetail
EndpointPOST /api/summary/analyze (tokenless — no Zoho credentials are accepted)
What is sentThe contact context the user is currently viewing: contact fields (name, email, phone, account, lifecycle stage, last activity), account details, a summary of financial status (overdue totals/counts, recent payments), and open support tickets
PurposeSolely to generate the AI strategic summary shown in the widget
RetentionNot persisted. Held only in an in-memory cache for 15 minutes, then evicted; cleared on restart
Rate limits30 requests/minute per IP; 200 KB request cap

4.2 In-Memory Cache

Smart Assistant uses an in-memory TTL cache (MemoryCache) so an unchanged summary is not regenerated on every page load:

5. Storage & Retention

Data TypeStored?Retention
CRM contact details ✗ Not stored Rendered live in the browser; discarded
Financial records (Books) ✗ Not stored Rendered live in the browser; discarded
Support tickets (Desk) ✗ Not stored Rendered live in the browser; discarded
AI-generated summaries Cached in memory 15 minutes, then evicted; never written to disk
Operation logs Rotating logs Rotated at ~5 MB; retention is configurable
Anonymous usage counters Aggregated Daily aggregate counts; no customer content

In the Connection-based flow there is no token store, so there is no stored credential data to retain or delete. Customers who previously used the legacy standalone linking mode (superseded by the Connection and not used by Marketplace installations) can have their encrypted token entry removed by disconnecting or by contacting support.

6. Third-Party Services

Smart Assistant relies on a small number of service categories:

CategoryRoleData
Zoho CRM, Books, Desk APIs and the Connection authorization All business data stays within Zoho; the Connection is bound to your organization and its data center
AI model provider Generates the optional strategic summary Receives the viewing context described in §4.1; used only to produce the response
Cloud hosting provider Runs the backend that serves pages and runs the AI summary Hosts the service, logs, and anonymous usage counters

6.1 AI Model Provider

The AI summary is generated through a third-party AI model API. The default provider is Google Gemini; the provider is configurable by the operator (other OpenAI-compatible providers can be selected). The provider receives only the contact context described in §4.1 and returns generated text. Data sent to the provider is not used by us for any purpose other than producing the summary.

If no AI provider is configured, the AI summary feature is disabled and no data leaves our backend.

6.2 Zoho

Smart Assistant communicates with the Zoho CRM, Zoho Books, and Zoho Desk APIs provided to your organization, and with Zoho’s authorization service for the Connection. Your data remains in your Zoho organization and its data center; Smart Assistant does not copy it elsewhere.

6.3 No Other Third Parties

Smart Assistant does not use advertising networks, tracking pixels, third-party analytics SDKs, or data brokers.

7. Data Processing & GDPR Compliance

7.1 Lawful Basis

Smart Assistant processes Zoho data on behalf of the organization’s administrators and users, under the legitimate interest of providing business intelligence within the existing CRM workflow. The extension:

Where Smart Assistant processes personal data at the direction of a customer organization, the customer acts as data controller and Smart Assistant as processor.

7.2 User Rights

RightHow It’s Handled
AccessAll data is displayed in the widget at the moment of access; we hold no stored copy to request
RectificationData is read from Zoho directly — edit it in Zoho to see changes reflected
ErasureRemove the extension / delete the Connection; the AI summary cache expires within 15 minutes
Data PortabilityData lives in Zoho — use Zoho’s export features
Restrict processingDisable the AI summary (no provider configured) or remove the extension

7.3 To Remove All Data

  1. Uninstall Smart Assistant or delete its Connection in Zoho CRM (Setup → Developer Hub → Connections) — this revokes the organization’s authorization.
  2. Any cached summary expires automatically within 15 minutes (or immediately on server restart).
  3. Aggregate usage counters and operation logs age out per §9.

8. Security Measures

AreaMeasure
AuthorizationZoho CRM Connection with read-only scopes — no password collection, no credentials handled by us
TransportTLS 1.2+ (HTTPS) for all communications
Least privilegeEvery requested scope is read-only; access follows the user’s existing Zoho permissions
Input validationAPI inputs are validated; request size is capped
Abuse protectionPer-IP rate limiting on the AI summary endpoint
HTTP securityStandard security headers applied; widget HTML is served no-cache
IsolationBackend runs as a managed container with minimal privileges
LoggingNo tokens, payloads, or business data written to logs

9. Logs & Usage Counters

9.1 Operation Logs

Our servers keep standard operation logs for reliability and security monitoring:

Logs may contain an IP address and user-agent as part of a standard access record — no other personal data is recorded.

9.2 Anonymous Usage Counters

To understand load and cost, we keep aggregate daily counters: the number of AI summary requests and provider calls, the provider name, token counts, latency, and failure counts. These counters contain no customer content and no identifiers — they are totals, not per-user records.

10. Your Rights & Contact

To exercise a data right, ask a privacy question, or request deletion of any of the limited data described above:

We aim to respond to data requests promptly and will confirm what (if anything) we hold and what action we have taken.